Skip to main content
Every action in the Operations domain is a governed capability with defined authorization, scope, and a receipt. Capabilities ensure that only authorized actors can change state, and every change leaves a trace.

Read Capabilities

  • ops.request.read — View request details and linked tickets
  • ops.asset.read — Query asset inventory and assignment history
  • ops.vendor.read — Access vendor profiles and risk scores
  • ops.policy.read — Read active policies and their scopes
  • ops.kpi.read — View operational metrics and trend reports

Write Capabilities

  • ops.ticket.update — Change ticket status, assignee, or priority
  • ops.asset.update — Modify asset assignment, location, or status
  • ops.vendor.update — Update vendor contact, risk tier, or contract dates
  • ops.approval.submit — Create a new approval request with linked evidence
  • ops.approval.decide — Approve or reject a pending request within your scope

Communication Capabilities

  • ops.ticket.comment — Add a public or internal comment to a ticket
  • ops.vendor.message — Send a templated message to a vendor contact
  • ops.broadcast.policy — Publish a policy update to affected queues

Workflow Capabilities

  • ops.workflow.requestFulfillment — Trigger the full request fulfillment pipeline
  • ops.workflow.vendorOnboarding — Kick off due diligence and contract review steps
  • ops.workflow.assetProvisioning — Initiate procurement, assignment, and record creation
  • ops.workflow.approvalRouting — Route an approval through delegation and escalation rules
  • ops.workflow.kpiReview — Launch metric collection, normalization, and alert evaluation
Capabilities are resolved at runtime against the actor identity, the target entity, and the active policy set. A capability denied at authorization returns a reason code that Twin surfaces for escalation.